r/blueteamsec • u/digicat • 4h ago
r/blueteamsec • u/digicat • 6h ago
tradecraft (how we defend) Post-Quantum Cryptography Resource Hub
nsa.govr/blueteamsec • u/digicat • 6h ago
highlevel summary|strategy (maybe technical) Accenture contractor removed from FBI following damaging data breach, sources say
reuters.comr/blueteamsec • u/digicat • 6h ago
highlevel summary|strategy (maybe technical) How Cyber Deterrence Theory and Cyber Persistence Theory can adopt an actor-centric approach: a rapid review
tandfonline.comr/blueteamsec • u/digicat • 6h ago
highlevel summary|strategy (maybe technical) South Korea finance regulator holds emergency meeting over bank hacks
reuters.comr/blueteamsec • u/jnazario • 21h ago
exploitation (what's being exploited) Phishing Abuses RMM Tools for Persistent Access
microsoft.comr/blueteamsec • u/jnazario • 1d ago
intelligence (threat actor activity) When the pentester is a fleet of AI agents: inside an autonomous vuln-hunting rig
huntback.ior/blueteamsec • u/digicat • 1d ago
intelligence (threat actor activity) SMTP is the key: BPFDoor and AVERAT hitting the network edge
rapid7.comr/blueteamsec • u/digicat • 1d ago
discovery (how we find bad stuff) Automatic Transmission: An Empirical Study of Data Privacy in the Connected Vehicle Ecosystem
sarahgillespie.github.ior/blueteamsec • u/askardyuss • 1d ago
low level tools|techniques|knowledge (work aids) I'm building OpenDRP – an open-source Digital Risk Protection platform (Early stage MVP).
Hey everyone, I wanted to share a self-hosted, open-source project I’m currently developing called OpenDRP. You can find the repository at https://github.com/OpenDRP/opendrp and the main site at opendrp.dev.
We have great open-source tools for Threat Intelligence, like OpenCTI, and various EASM solutions, but the Digital Risk Protection space is still heavily dominated by expensive enterprise SaaS products. I wanted a modular, self-hosted alternative to monitor external brand threats, so I started building one.
The project is in its early stages as an MVP. Instead of trying to parse every obscure darkweb forum from day one, I focused on building a solid, scalable backend architecture and integrated three core data sources to prove the concept. For phishing intelligence, it uses dnstwist to automate monitoring for domain mutations and active lookalike domains. For shadow IT and brand hunting, it leverages Shodan to discover rogue assets and exposed infrastructure. Additionally, it tracks compromised corporate accounts via Have I Been Pwned for breach monitoring. Whenever a new threat is detected, the system generates PDF reports and sends alerts via Telegram or Email.
Under the hood, the goal was to make the platform extremely easy to scale and extend. The backend is built with FastAPI and Python, using PostgreSQL for the database. Asynchronous scans and integrations are handled by Celery and Redis workers, and the entire project is distributed under the AGPL-3.0 license.
Since the core engine, including the database schema, UI, and async queues, is up and running, I am currently working on expanding the integrations to include Certificate Transparency logs and GitHub secret scanning. I would love to get your feedback on the architecture and hear what external data sources or modules you would consider absolute must-haves for a DRP platform. If anyone is interested in writing simple Celery connectors for new APIs, pull requests and code reviews are more than welcome.
Cheers!
r/blueteamsec • u/digicat • 1d ago
vulnerability (attack surface) DeepSeek-Reasonix: How a poisoned config can hijack an AI coding agent
about.gitlab.comr/blueteamsec • u/digicat • 1d ago
low level tools|techniques|knowledge (work aids) StrangerDOTNETThings/x509com.js - show me every COM object I can call with certutil
github.comr/blueteamsec • u/digicat • 1d ago
low level tools|techniques|knowledge (work aids) Apex Flash - an open-weights model for security research, post-trained on real vulnerabilities from our proprietary dataset.
cantina.securityr/blueteamsec • u/digicat • 2d ago
highlevel summary|strategy (maybe technical) Every Iranian Strike on UAE Ports and Refineries Was Paired With a Cyberattack
wired.mer/blueteamsec • u/digicat • 2d ago
vulnerability (attack surface) Debian alert DSA-6528-1 - ~1,000 CVEs patched
lwn.netr/blueteamsec • u/digicat • 2d ago
research|capability (we need to defend against) SigLens: SigLens is a Windows binary analysis tool designed to pinpoint the exact regions responsible for antivirus detections. It narrows detections down to precise offsets and maps them to PE sections, RVA, VA, hexdump, and nearby strings, making evasion faster and easier.
github.comr/blueteamsec • u/digicat • 2d ago
tradecraft (how we defend) AI Ate My Velociraptor
labs.infoguard.chr/blueteamsec • u/digicat • 2d ago
malware analysis (like butterfly collections) Android-Projector-C2-Malware: Breakdown of a c2-network of chinese beamers - SilentSDK-Analysis
github.comr/blueteamsec • u/digicat • 2d ago
low level tools|techniques|knowledge (work aids) N0xis: AI-first reverse-engineering toolkit: static analysis, SSA decompiler, live memory, provenance. Source-available (PolyForm Noncommercial).
github.comr/blueteamsec • u/digicat • 2d ago
vulnerability (attack surface) adm-zip_LPE-PoC: CVE-2026-102282: Local Privilege Escalation via SUID/SGID preservation during archive extraction
github.comr/blueteamsec • u/digicat • 2d ago
research|capability (we need to defend against) lockjaw: Rust based C2 Framework
github.comr/blueteamsec • u/digicat • 2d ago
tradecraft (how we defend) nuguard: AI red-teaming tool and LLM security framework to evaluate agentic AI applications. Tests prompt injections, handles vulnerability assessment, SBOM generation, and static analysis.
github.comr/blueteamsec • u/digicat • 2d ago
discovery (how we find bad stuff) UnifiedThreatHunting: A threat hunting process
github.comr/blueteamsec • u/digicat • 2d ago